Play 20
Anomaly Detection
Real-time anomaly detection with streaming analysis and AI enrichment.
Events flow through Event Hub, Stream Analytics detects statistical anomalies in real time, GPT-4o enriches alerts with natural language explanations and suggested actions. Cosmos DB stores event history for trend analysis. Azure Functions trigger downstream workflows (PagerDuty, Teams, email).
Architecture Pattern
Streaming anomaly detection, event-driven, AI enrichment, alerting
Azure Services
DevKit (.github Agentic OS)
- agent.md — root orchestrator with builder→reviewer→tuner handoffs
- 3 agents — Anomaly Builder (gpt-4o), Reviewer (gpt-4o-mini), Tuner (gpt-4o-mini)
- 3 skills — deploy (103 lines), evaluate (106 lines), tune (110 lines)
- 4 prompts — /deploy, /test, /review, /evaluate with agent routing
- .vscode/mcp.json — FrootAI MCP with Log Analytics + OpenAI inputs + envFile
TuneKit (AI Config)
- config/detection.json — detection models, sensitivity, thresholds
- config/alerts.json — alert rules, severity mapping
- config/enrichment.json — AI analysis prompts
Tuning Parameters
Machine evidence
FrootAI evidence lifecycle
This is an internal evidence maturity label, not third-party certification, accreditation, legal compliance, or a production guarantee. Missing or expired evidence demotes automatically; catalog claims cannot promote a play.
This play currently has design evidence only. A runnable scenario, endpoint evaluation, and build receipts are the next contiguous gates.
Repo Intelligence
v1A no-clone, revision-pinned map for agents and humans. Observed evidence is separated from inferred flow so the output stays useful without pretending to be a full call graph.